不正URLへのアクセス、不正メールの受信
- 
					メール受信した
 弊社お客様0社 URLアクセスした
 弊社お客様1社
- 
					2024/08/08
					
 ※2024/08/08 更新
 マルウェア感染させると考えられるURLを検知(2024/08/08)
■IoC(※1)
| Type: | IOC: | Signature: | 
|---|---|---|
| URL | hxxps://xza[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://alphawatchrmf[.]com/cdn-vs/original[.]js hxxps://alphawatchrmf[.]com/cdn-vs/main[.]php hxxps://alphawatchrmf[.]com/cdn-vs/download[.]php hxxps://veb[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://cqp[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://zead[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://gdhnc[.]donors[.]eucharisticjesus[.]net/orderReview hxxps://myanswerpronto[.]com/cdn-vs/22per[.]php hxxps://velellablue[.]com/cdn-vs/22per[.]php | FAKEUPDATES | 
| URL | hxxp://23[.]94[.]247[.]40:7890/OBjb hxxp://210[.]71[.]231[.]3/like[.]exe | Cobalt Strike | 
| URL | hxxp://147[.]45[.]44[.]104/prog/66af31c75d213_123p[.]exe hxxp://193[.]32[.]162[.]25/pages/Update[.]exe | Coinminer | 
| URL | hxxp://147[.]45[.]44[.]104/prog/66b1c36969eae_main[.]exe hxxp://147[.]45[.]44[.]104/yuop/66b1f63c9578f_doz[.]exe | Vidar | 
| URL | hxxp://91[.]92[.]242[.]99/ZqXZaKPIFpdXHH159[.]bin hxxps://www[.]synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxps://mail[.]synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxp://mail[.]synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxp://synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxp://www[.]synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxps://synergyinnovationsgroup[.]com/YuzCf148[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Skylightets[.]chm hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Coffer[.]dsp hxxps://ranchoboscardin[.]com[.]br/dc/Asynartete[.]csv hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Antibureaukratiske[.]thn hxxps://ranchoboscardin[.]com[.]br/dc/Elendil[.]sea hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Maalmndene[.]aca hxxps://ranchoboscardin[.]com[.]br/dc/Coffer[.]dsp hxxps://www[.]ranchoboscardin[.]com[.]br/dc/bravurariers[.]jpb hxxps://ranchoboscardin[.]com[.]br/dc/Antibureaukratiske[.]thn hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Dividedness[.]prx hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Asynartete[.]csv hxxps://ranchoboscardin[.]com[.]br/dc/Dividedness[.]prx hxxps://ranchoboscardin[.]com[.]br/dc/bravurariers[.]jpb hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Elendil[.]sea hxxps://ranchoboscardin[.]com[.]br/dc/Maalmndene[.]aca hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Neobotany[.]ttf hxxps://ranchoboscardin[.]com[.]br/dc/Skylightets[.]chm hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Greensand[.]ocx hxxps://ranchoboscardin[.]com[.]br/dc/Neobotany[.]ttf hxxps://ranchoboscardin[.]com[.]br/dc/Frysetjet[.]afm hxxps://ranchoboscardin[.]com[.]br/dc/Greensand[.]ocx hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Frysetjet[.]afm hxxps://www[.]ranchoboscardin[.]com[.]br/dc/Sabellarian[.]xtp hxxps://ranchoboscardin[.]com[.]br/dc/hYIMYakzawECsYBwW56[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/TVLdv58[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/TVLdv58[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/AMqoYbIPYLOcGMZVU24[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/hYIMYakzawECsYBwW56[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/yJjosxRDWJDyinhY170[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/AMqoYbIPYLOcGMZVU24[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/yJjosxRDWJDyinhY170[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/uUKNOfmYcaMfWIety113[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/uUKNOfmYcaMfWIety113[.]bin hxxps://ranchoboscardin[.]com[.]br/dc/JdaAc179[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/JdaAc179[.]bin hxxps://www[.]ranchoboscardin[.]com[.]br/dc/PsPyggxVUPQVS252[.]bin hxxps://ranchoboscardin[.]com[.]br/cs/Smalmed[.]jpb hxxps://www[.]ranchoboscardin[.]com[.]br/cs/Smalmed[.]jpb hxxps://www[.]ranchoboscardin[.]com[.]br/cs/Rrknoglerne[.]asd hxxps://ranchoboscardin[.]com[.]br/cs/Rrknoglerne[.]asd hxxps://www[.]ranchoboscardin[.]com[.]br/cs/yGxZBUGU144[.]bin hxxps://ranchoboscardin[.]com[.]br/cs/yGxZBUGU144[.]bin | CloudEyE | 
| URL | hxxp://192[.]3[.]109[.]147/18/sweethoneygirlkisseronlipstosweet[.]gIF hxxp://192[.]3[.]193[.]155/xampp/uhj/picturegreatforeveryonetokissherlips[.]gIF hxxp://192[.]3[.]193[.]155/xampp/uhj/mlm/sincesheiseverbuildnewthingentirelifewithouthavinganythingbczshelovedherwithentiretimetogetmebackwithnewsupportof________girlsheretokissurlip[.]doc hxxp://192[.]3[.]109[.]147/88/mssc/mygirlistotalchangeswithentirethingstobeunderstandeverythingwillbegreatalwaysgreatireallybelievethingsareback________greatthingstotal[.]doc hxxp://192[.]3[.]109[.]147/88/greatbiscutforbabieshealthgreatthings[.]gIF hxxps://sudocumentodepago[.]click/descargas/JULIO2024R[.]txt hxxps://sudocumentodepago[.]click/upload/aa[.]exe hxxps://sudocumentodepago[.]click/upload/dmw[.]exe hxxp://192[.]3[.]193[.]155/xampp/uhj/GDFG[.]txt | Remcos | 
| URL | hxxp://80[.]66[.]75[.]214/g8djmsaxA/Plugins/clip64[.]dll hxxp://80[.]66[.]75[.]214/g8djmsaxA/Plugins/cred64[.]dll | Amadey | 
| URL | hxxp://45[.]151[.]62[.]96/setup[.]exe | DarkGate | 
| URL | hxxp://antivirusaway[.]top/pipePhpSecureGeolongpollDbBasedatalifedle[.]php hxxp://241622cm[.]n9shteam1[.]top/PipejavascriptrequestGeoCpulongpollBigloaddefaultbasePublic[.]php | DCRat | 
| URL | hxxps://nisvsorupsssazusxehome[.]xyz/MTA2MzQzMjEyMzM3/ | Coper | 
| URL | hxxp://69[.]166[.]230[.]221/113/sahost[.]exe hxxp://69[.]166[.]230[.]221/xampp/ibnet/IEnetworks[.]hta hxxps://pastecode[.]dev/raw/baskrfz1/paste1[.]txt hxxp://192[.]210[.]150[.]33/88/sweetdresswearwithgirlstyle[.]gIF hxxp://192[.]210[.]150[.]33/88/mssc/wecreatednewentertainmenttounderstandhowperfectyourlovertogetmebackwithenitrethingstogbeworkwithentirenetwork_________sheismygirlwhoilovedtruly[.]doc | Formbook | 
| URL | hxxp://147[.]45[.]44[.]104/yuop/66b274e0e1b95_shapr3D[.]exe | Lumma Stealer | 
| URL | hxxp://91[.]92[.]243[.]78:8080/TARGETS/Pedro_1/Reader_en_install[.]exe hxxp://91[.]92[.]243[.]78:8080/PureHvnc/Reader_en_install[.]exe hxxp://91[.]92[.]243[.]78:8080/hvnc[.]exe | PureCrypter | 
| URL | hxxp://103[.]45[.]247[.]13/Aqua[.]arm4 hxxp://103[.]45[.]247[.]13/Aqua[.]arm5 | Bashlite | 
| URL | hxxp://185[.]215[.]113[.]19/inc/Cbmefxrmnv[.]exe | SystemBC | 
| URL | hxxp://185[.]215[.]113[.]19/inc/clsid[.]exe hxxp://mail[.]synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxps://mail[.]synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxp://www[.]synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxps://www[.]synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxp://synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxps://synergyinnovationsgroup[.]com/IMjqggfGsjOkXDuwwaMHlATCTLUF214[.]bin hxxps://sudocumentodepago[.]click/upload/aa[.]vbs hxxps://sudocumentodepago[.]click/upload/dmw[.]vbs hxxps://107[.]172[.]31[.]19/88/sahost[.]exe hxxps://107[.]172[.]31[.]19/xampp/ku/88[.]hta hxxp://107[.]172[.]31[.]19/xampp/ku/88[.]hta hxxp://107[.]172[.]31[.]19/88/sahost[.]exe | Agent Tesla | 
| URL | hxxp://185[.]215[.]113[.]19/inc/systems[.]exe | RedLine Stealer | 
| URL | hxxp://192[.]3[.]176[.]138/106/sahost[.]exe hxxp://192[.]3[.]176[.]138/105/sahost[.]exe hxxp://192[.]3[.]176[.]138/xampp/ozon/oz/106[.]hta hxxp://192[.]3[.]176[.]138/60/sahost[.]exe hxxp://198[.]46[.]174[.]139/95/wahost[.]exe hxxp://198[.]46[.]174[.]139/50/regasm[.]exe hxxp://192[.]3[.]176[.]138/55/sahost[.]exe hxxp://192[.]3[.]176[.]138/95/sahost[.]exe hxxp://192[.]3[.]176[.]138/70/sahost[.]exe hxxp://198[.]46[.]174[.]139/60/regasm[.]exe | Snake Keylogger | 
| URL | hxxp://87[.]106[.]114[.]72/rat[.]exe | Quasar RAT | 
| URL | hxxps://ranchoboscardin[.]com[.]br/dc/xmay[.]txt hxxps://www[.]ranchoboscardin[.]com[.]br/dc/xmay[.]txt | XWorm | 
| URL | hxxps://didsit[.]com/data[.]php | NetSupportManager RAT | 








